EXPOSURES › CVE-2022-41352
CVE-2022-41352
HIGH ⌖ ON CISA KEV · EXPLOITEDSynacor's Zimbra Collaboration Suite (ZCS) had an unpatched RCE flaw allowing attackers to upload arbitrary files and gain access to any user account.
Synacor's Zimbra Collaboration Suite (ZCS) suffered from a critical file upload vulnerability that remained unpatched for an extended period, enabling attackers to upload malicious files and compromise any user account. This persistence of unpatched vulnerabilities in core components like mailbox import, Classic UI, and postjournal services has been actively exploited by ransomware campaigns.
Shame score — Chronic vulnerability management failure enabling active exploitation by ransomware.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.